Quantcast
Channel: Shavlik User Community : All Content - Ivanti Patch for Windows
Viewing all 2126 articles
Browse latest View live

Is there a way to create a report for Microsoft patches downloaded within the last 30 days

$
0
0

RE: Ivanti Management Console ver 10.1.30.401

Patch and Compliance Reporting

 

I need to create a report that lists all of the most recent Microsoft patched downloaded in the last month. Specifically I am looking for those with vulnerability levels of Critical/High, Important/High and Moderate. I am a new user and so far have not been able to find a way to query for these updates.

 

Thanks in advance for any assistance!

 

James


Access Denied to Ip XXXXXX; Cradentials may be invalid

$
0
0

When we are trying to Scan(Machine Group and Patch templates), scan is getting failed on " Resolve Machine To Scan" step.

When we select "View Results" it gives Status as "Access Denied to Ip XXXXXX; Cradentials may be invalid" with error code "106".

 

Software on Machine: Windows 10 64-bit OS.

Please refer the attached screen shot.

Agent Failing Registration at 50%

$
0
0

Symptoms

 

To diagnose this issue, there are many symptoms that may need to be considered:

 

Cause

 

There are many reasons the registration could fail, but generally the above symptoms indicate some sort of communication issue with the agent being able to reach the Protect console for registration.

 

Resolution

 

Start by first checking that some simple connection tests work from the agent system to the console system:

  • Ensure you can ping the console system.
    • If you can't ping the console system, either you have no connection from the agent to the console system, or (rarely) you may have ICMP disabled.
  • Ensure you are able to successfully resolve the console system by nslookup.
    • Make sure the results of both forward and reverse nslookup match. Ensure there is no problem with machine name resolution.
  • Can you telnet to the console system over port 3121 successfully?
    • Port 3121 is used for agent communication back to the console. This is a port requirement and is not configurable.
  • Can you telnet to the target machine over port 4155 successfully?
    • Port 4155 is used for the console to communicate to the target machine. This is a port requirement and is not configurable.
  • Make sure that TLS 1.0 is enabled or TLS 1.2 is properly configured as is mentioned in this document Disabling TLS 1.0 may causes issues with Protect and Patch for Windows Servers

 

If the above tests are all successful, continue to the next steps in troubleshooting:

  • Ensure that the name, FQDN, or IP the agent is attempting to resolve exists in the Console Alias Editor within the Protect console.
  • In many of the log snippets above you can see that the agent attempts to register with https://Host.fqdn:3121/ST/Console/AgentRegistration/Registration
    • Test putting the URL from your log into an Internet Explorer window to see if you can successfully navigate to it. (On the agent system)
      • If the test is successful you would see a screen displayed stating something along the lines of, "A service was created".
        • If this test works the agent should by all means be able to successfully register successfully.
        • Follow the steps in this document: Agent - Complete Uninstall then attempt installation again.
        • Contact support if it still fails.
      • If the test fails with an "Internet Explorer cannot display the webpage" message, continue to the next step.
    • Run a test on the agent system to see what security protocols are enabled.
      • Qualys SSL Labs - Projects / SSL Client Test is a good site to test with.
      • You may not have a security protocol enabled or something is incorrect in the configuration.
      • If no protocols are enabled, a secure web connection cannot truly be established, thus causing the agent registration to fail.
        • The Microsoft article TLS/SSL Tools and Settings: Logon and Authentication covers how to ensure protocols are enabled or disabled.
        • Generally you may need to investigate settings in the following registry key:
          HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols

Additional Information

 

If the agent is failing to install at a different percentage mark or when manually installing, you may want to consider reviewing the following documents:

Agent Failing at 67% (Registration Failure)

Manual installation of agent fails on registration.

 

Affected Product(s)

 

Shavlik Protect 9.x

Creating report to find Spectre/Meltdown patches

$
0
0

I would like to create a custom report on the SQL Server backend database to find the status of all servers with regard to the installation (or lack thereof) of the Spectre/Meltdown patches.  I'm sure that this is just a customization of the Patch Status Detail Report, but I'm curious about what people are doing for the filter clause?  Are you filtering by Bulletin ID?  Surely I can't be the first person who has asked this, ...

Windows 10

$
0
0

Can Shavlik Protect Standard 9.2 be hosted from a Windows 10 Client system?

Patching for Office 365 / 2016 ProPlus clarification

$
0
0

I am getting ready to deploy the latest version of Office 2016 via Office 365.

 

From this KB: Office 365 Support for Shavlik Protect/Ivanti Patch for Windows Servers  I understand that Ivanti Patch can manage deployment of patches for Click To Run versions of Office 2016 on the Semi-Annual 'channel' (Which I think is the new name for Deferred?). Just to confirm, as long as I leave the default patch download path pointed to Microsoft's CDN and the auto updates turned off in the Office applications then Shavlik patch will still find and 'deploy' patches to Office when they become available?

 

Thanks

patch error 2147483647. sfc /scannow comes up empty. kb3181988 Windows reports manual update not applicable.

$
0
0

patch error 2147483647.

sfc /scannow comes up empty.

kb3181988 Windows reports manual update "not applicable to this system."

Is there a problem with the .XML patch detection?

How To: Run a Diagnostic Patch Scan When Unable to Perform a DPDTrace

$
0
0

Purpose

 

The purpose of this document is to instruct how to run a diagnostic patch scan when you are unable to perform a DPDTrace for a detection issue.

 

 

Overview

 

  1. Go to Tools > Options > Logging in your console and set the Logging to All and check the Diagnostic patch scanning Checkbox. Note as the message below the Diagnostic option says, you should only turn this option on at the request of Support.

 

  2. Save your changes and select to restart the service now then close your console, then stop either the Shavlik Protect Console Service in 9.2 or the Ivanti Patch for Windows Servers service in 9.3.

  

 

   3. Go to C:\ProgramData\Landesk\Shavlik Protect\Logs and delete or move the contents of the directory.

 

    

   
  4. Restart the console service from step 2 then open your console and scan the machine that Support has requested the diagnostic scan for using the scan template that Support specifies. For instance, if the problem patch on the machine is a security patch, you would use the security patch scan          template.

Scan Results.PNG

 

   5. Save a screenshot similar to the screenshot above showing the machine name, definition date, scan template, Bulletin ID, and Q number of the patch having the issue.

 

   6. Go to Tools > Options > Logging and uncheck the Diagnostic Patch scanning checkbox and save your changes.

 

   7. Close your console, stop the console service from step 2, and zip up the contents of the C:\ProgramData\Landesk\Shavlik Protect\Logs folder.

 

   8. Send the zipped Logs folder from step 7 and the screenshot from step 5 to Support.

 

 

Additional Information

 

You will still need to obtain Registry Exports from the problem client machine to send to Support along with the Diagnostic Patch Scan or DPDTrace. You will find instructions for obtaining these Registry Exports here Batch File for Obtaining Registry Exports for Detection Related Issues

 

 

Affected Products

 

Ivanti Patch for Windows Servers 9.3

Shavlik Protect 9.2


Getting Error -1 when scanning any machine

$
0
0

This just started today.  Shavlik can still contact all of the PCs but I don't get any scan results, just Error Code -1.

I've already rebooted the Shavlik server.  There don't seem to be any other problems around the network today that might be related.

 

Any ideas?

Can't scan since Friday.

$
0
0

Since Friday 3-30-18 late afternoon, all scans produce Error code 900, critical error, send logs to support. We believe you all pushed an update Friday?? Thanks!

KB4088883

$
0
0

I had a Windows Server 2012 crash after patching last weekend.  After some trial and error including hour long restores I narrowed down the issue to KB4088883:


Ivanti Patch News Bulletin: Preview of Monthly ... | Ivanti User Community

 

I found some help from a Microsoft forum but no information on whether there is a proper way to install the patch or if a corrected version would come out later:

https://social.technet.microsoft.com/Forums/windowsserver/en-US/c35068db-846d-43f0-b7a1-8f4d53bab997/suspected-problem-with-kb408883?forum=winserver8gen

https://social.technet.microsoft.com/Forums/windowsserver/en-US/c35068db-846d-43f0-b7a1-8f4d53bab997/suspected-problem-with-kb408883?forum=winserver8gen

 

So my questions are 1) Is anyone else having the same issue on their Windows Server 2012 Servers and what did you do to resolve the issue and 2) How do I exclude this patch from a scan or deployment so it does not get pushed out again and crash my server?  I tried following the instructions in the following KB but had no luck finding the update:

 

How To: Include or Exclude Specific Patches in Scan Results in Shavlik Protect

 

Any help you guys can give would greatly be appreciated.  Thanks!

How to deploy KB4099950 when only Security patches are deployed?

$
0
0

So KB4099950 (https://community.ivanti.com/docs/DOC-66843 ) has been released to sort out the NIC issues that MS18-03-SO7 Q4088878 introduced.  My normal scan template only scans for, and therefore deploys, Security Patches and Security Tools.  As KB4099950 is classed as a Non-security patch, is it possible I could deploy this using my normal scanning template?  Custom Action on the deployment template?  How?  I should add I'm still on Protect Standard 9.2.0 build 5119.

 

Cheers, Dilip.

Show Hidden Sidebar In Ivanti Patch for Windows

$
0
0

Purpose

 

This document will show how to unhide the sidebar in the main window of Shavlik Protect.

 

 

Description

 

You are unable to see the sidebar in the main window of Shavlik Protect:

Hidden Sidebar.PNG

 

 

Resolution

 

To unhide the sidebar in Shavlik Protect, click the arrow in the center of the very edge of the console screen:

 

Hidden Sidebar Fix.PNG

Hidden Sidebar Fix After.PNG

 

 

Affected Product(s)

Ivanti Patch for Windows Servers 9.3 +

Shavlik Protect 9.2

Finding a specific MS patch

$
0
0

I have trouble finding specific MS patch: KB4100480

 

I have opened View -> Patches, selected all patch type and all Vendors and Families.

Unfortunately the patch above is not found:

 

 

Why is that?

Protect Migration Tool

$
0
0

Hi,

 

Where can I download the Patch for Windows Server Migration Tool from?

There only seems to be links to PDFs on how to use it and no link on where to get it from.

 

Steve


Need nullpatch.exe download link for disconnected networks

$
0
0

I am running on a disconnected network and need to acquire the nullpatch.exe patch. I am looking for a link to download the patch.

Will PWS will have any effect on App-V delivered programs

$
0
0

I am curious as to whether PWS will have any effect on App-V delivered programs, while patching those installed locally.  Do I need to coordinate the patch versions of both or can I maintain them independently.  Thank you.

SCCM Security Scope setting causes Ivanti Patch functionality issues

$
0
0

Purpose

 

Although this is more a SCCM issue, Ivanti Patch for SCCM is directly affected.  This document will outline how to resolve Ivanti Patch for SCCM functionality issues caused when the SCCM user's Security Scope isn't set to: All instances of the objects that are related to the assigned security roles.

 

Overview

The requirements for Shavlik Patch are located here:  How To: Verify your SCCM user is a member of the WSUS Administrators Group

In addition requirements from the document, the SCCM user must be assigned to the All instances of the objects that are related to the assigned security roles Security Scope.

 

This is an example of a SCCM Administrator who does not have All Instances Of The Objects That Are Related To The Assigned Security Roles set.

Account.PNG

 

The AutoPublish.log located in this folder: C:\users\username\Shavlik\Shavlik Patch folder will contain these errors:

SMS Error: Microsoft.ConfigurationManagement.ManagementProvider.WqlQueryEngine.WqlQueryException You do not have security rights to perform this operation. AutoPublish 1/31/2017 3:14:14 PM 4 (0x0004)

Generic failure AutoPublish 1/31/2017 3:14:14 PM 4 (0x0004)

Your Configuration Manager security settings may be limited. Your security role should be 'Full Administrator' and your security scopes should be 'All instances of the objects that are related to the assigned security roles'. AutoPublish 1/31/2017 3:14:14 PM 4 (0x0004)

Error - AutoPublish returned code 18: Error cleaning up categories AutoPublish 1/31/2017 3:14:14 PM 1 (0x0001)

 

Resolution

 

     1. Open SCCM and select Administration.

     2. Expand Security and select Administrative Users.

     3. Locate the user used to log into the SCCM server and open its Properties.

     4. On the Security Scopes tab select 'All Instances Of The Objects That Are Related To The Assigned Security Roles'.

     5. Select OK..

 

Additional Information

 

There are two known workarounds if the option 'All Instances Of The Objects That Are Related To The Assigned Security Roles' is greyed. (pictured above)

 

  • Log into the Windows as the original user who installed the SCCM server.  This is the only user able to change the Security Scope option.
  • If all else fails, Microsoft advises to rebuild your SCCM environment.

 

Affected Product(s)

 

Ivanti Patch for SCCM

Ivanti Patch for Windows Servers Reports

$
0
0

I'm using Ivanti Patch for Windows Servers Standard 9.3 Build 4510.

 

What is the best method to get a report of all servers who are missing either an operating system service pack or a SQL server service pack?   I reviewed the options in Tools\Create Report - these just left me confused.  Perhaps there is already something canned that I'm missing or a better documented process for creating a report that I could be directed towards.

 

Thanks

Patches are not being downloaded or pushed to the node

$
0
0

I am using Shavlik Protect 9.3. I was patching a new server and everything was going fine. I rebooted after some patches and scanned again. This time the server only had 6 missing patches. I tried to push these patches and nothing happens. All other servers seem to be fine. I thought it was the Scheduler on the server, so I followed these directions to uninstall (How To: Uninstall & Reinstall The Shavlik (ST) Remote Scheduler Service On A Single Machine ). This did not resolve the issue and on the next scan/deploy it did not install the scheduler. It opens the deployment tracker once I request the patches to be deployed, but I can immediately click "Clear all completed" and it closes the window. It's like the Shavlik server has an issue with the client. Any help is appreciated.

Viewing all 2126 articles
Browse latest View live